SecurityFAQCopy as MarkdownFrequently asked questions about ARCY's security posture.Where is ARCY hosted, and is traffic encrypted in transit?Is our data encrypted at rest?Do you have Zero Data Retention (ZDR) with your AI provider?How are our API keys protected?Can ARCY employees see our customers' data?What internal access controls exist for the ARCY team?How do you isolate one customer's data from another?Do you offer dedicated infrastructure for enterprise customers?What stops Autopilot mode from taking an action we didn't authorize?Do you have a responsible disclosure program?Have you had an external penetration test?What is your incident response process?What happens to our data if we stop using ARCY?How do you handle SDK versioning and breaking changes?If ARCY itself goes down, does our app break too?Can we cap how much Autopilot mode can do, to control cost or runaway actions?Responsible disclosureHow to report a vulnerability and what is in and out of scope.What ARCY collectsThe session events the SDK collects during normal operation.